You build on GPT, Claude or Gemini. What is your part?
The model provider carries duties for the model. You carry duties for the system you built around it — and for what your users do with it.
Last reviewed:
Sound familiar?
- You assume the vendor's compliance page covers you. It covers the model, not your product.
- Model versions change under you, and nobody tracks what that did to behaviour or documentation.
- Your prompt, tools and retrieval layer changed the intended purpose, and nobody re-checked the classification.
- Data sent to the model crosses a boundary your privacy notice never described.
What we do
Split of duties
A concrete line between what your model vendor is responsible for and what stays with you — per system, in writing.
Vendor evidence review
We read the vendor documentation you are relying on and tell you what it actually promises, and where you are still exposed.
Version and change control
How model updates, prompt changes and tool additions are recorded, tested and reflected in your documentation.
Data flow check
What leaves your systems, where it is processed, what is retained, and whether your notices and contracts match reality.
Questions we get
Is a model vendor's compliance statement enough for us?
No. It reduces your work on the model layer, but obligations for the system you built — purpose, oversight, documentation, transparency towards your users — remain yours.
Does hosting the model ourselves change anything?
Yes, it moves more of the model-layer responsibility to you, including performance and safety characteristics. Open-weight self-hosting is not a shortcut past compliance, it is a shift of who has to prove things.
What happens when the vendor deprecates a model?
You need a documented migration path and a re-test, because behaviour changes with the model. We build that into the change-control rules rather than leaving it to whoever notices the email.
Tell us what's running in production.
We'll tell you what we'd check first — and what we wouldn't bother with.
Book a call